Skip to main content
Integrity & Safety

Security Policy

Cyber Scotland Connect takes the security of our community infrastructure and members seriously.

Supported Scope

This security policy applies to:

Confidential Disclosure

⚠️ Please DO NOT report security vulnerabilities through public GitHub issues.

If you believe you have discovered a vulnerability or misconfiguration:

  1. GitHub Private Vulnerability Reporting (Preferred):
    Submit a confidential advisory directly via theGitHub Security Advisory Tab ↗.
  2. Direct Contact:
    Email the core maintainers at hello@cyberscotlandconnect.com.

Response Commitments

48 HoursInitial acknowledgment of incoming report.
5 Business DaysTriage, assessment, and reproduction update.
Coordinated FixCollaborative disclosure with reporter credit.